AI Non-Human Identity Fundraising: Astrix, Oasis, Aembit

How Astrix Security, Oasis Security, Aembit, Clutch, Andromeda, Token Security, Natoma, Corsha, Entro, Britive, and AI-native non-human identity.

Raising Capital for AI Non-Human, Machine, Agent Identity & Secrets Startups

Non-human identity (NHI), machine identity, agent identity is the fastest-emerging security category — the 2024 Snowflake stolen-token wave (Ticketmaster, AT&T, Santander, LendingTree, Advance Auto Parts, 165+ tenants via non-MFA'd service accounts), Cloudflare, Okta post-Sisense compromise, GitHub OAuth-token compromise 2022-2024 waves, plus the explosion of AI agents (OpenAI Agents SDK, Anthropic Claude Agent SDK, MCP tool-calls, LangGraph, CrewAI, Temporal) forced every F500 CISO to accept that NHIs now outnumber human identities 45-80:1 and that OAuth-tokens, service-accounts, API-keys, SSH-keys, PATs, workload-identities, agent-identities are the new perimeter. Startups, product — Astrix Security ($85M+ total incl. $45M B Nov-2024 Menlo-Bessemer-CRV-F2 Capital, NHI discovery, posture, remediation, Github-Slack-Salesforce-Snowflake OAuth-app, service-account coverage), Oasis Security ($75M+ total incl. $35M A Jan-2024 Sequoia-Accel-Cyberstarts, NHI lifecycle, rotation, governance), Aembit ($45M+ total incl. $25M A Sep-2023 Acrew-Ballistic-Ten Eleven, workload-to-workload identity, policy, secretless), Clutch Security ($20M+ total incl. $8.5M seed Feb-2024 Lightspeed-Merlin, NHI-Guard, universal NHI-security-platform), Andromeda Security ($15M+ total incl. $10M seed May-2024 Foundation Capital, human, non-human IAM unified for cloud), Token Security ($27M+ total incl. $20M A Feb-2024 Notable-TLV Partners, machine-first identity, risk-based access), Natoma ($10M+ total incl. $6M seed Mar-2024 First Round-Dell Ventures, NHI governance), Corsha ($20M+ total incl. $12M A Ten Eleven, machine-to-machine identity, mTLS, PKI), Entro Security ($24M+ total incl. $18M A Nov-2023 Dell Ventures-StageOne, secrets, NHI-posture), Britive ($36M+ total incl. $20M B Pelion-Crosslink, cloud PAM, JIT for machines, humans), Apono ($16M+ total incl. $12.5M A Redpoint-New Era, JIT access for cloud, identities), P0 Security ($15M+ total incl. $8M seed Lightspeed-Palo Alto, machine, human identity), Teleport ($169M+ total incl. $110M C Nov-2021 Bessemer-Insight-Kleiner-S28-Y-Combinator, infrastructure-access, machine identity, Access Platform), StrongDM ($150M+ total incl. $54M B Feb-2022 Sequoia-Godfrey-Tiger, infrastructure-access, machine identity), Silverfort ($222M+ total incl. $116M D Jul-2024 Brighton Park-Greenfield-Acrew, unified identity, MFA-everywhere, service-account protection), Grip Security ($166M+ total incl. $41M C Sep-2024 YL-Third Point-Intel Capital, SaaS, NHI, shadow-SaaS), Savvy Security ($30M+ total incl. $17M A Canaan-Cyberstarts, browser-based identity, SaaS, NHI). Frontier, workload, agent identity — SPIFFE, SPIRE (CNCF, workload identity spec), OpenID, OAuth 2.1, OAuth Client Credentials, PKCE, FAPI 2.0, DPoP, FedCM, OIDC, SD-JWT, Verifiable Credentials, mDL (ISO 18013-5), OpenTelemetry-adjacent identity signals, plus MCP OAuth 2.1 profile (Anthropic Mar-2025) for AI-agent tool-authorization, plus Anthropic Claude Agent SDK, OpenAI Agents SDK, Cursor Background Agent, Devin sandbox agent-identity primitives. Established identity, PAM, secrets, PKI — Okta $OKTA, Auth0 (post $6.5B acquisition May-2021), Microsoft Entra ID, Entra Verified ID, Entra ID Governance, Purview, Defender for Cloud, Google Workspace, Cloud Identity, Chronicle-Mandiant, BeyondCorp, Amazon IAM, IAM Identity Center, Verified Permissions, Cognito, STS, OneLogin (One Identity, Clearlake), Ping Identity (Thoma Bravo take-private $2.8B Aug-2022, merged ForgeRock $2.3B Aug-2023), CyberArk $CYBR, Venafi acquisition $1.54B Oct-2024 (machine identity, code-signing, PKI leader), HashiCorp Vault, Boundary (IBM acquisition $6.4B pending Feb-2025), Delinea (Thycotic, Centrify merge, TPG Capital), BeyondTrust (Bomgar), Saviynt ($205M growth AB Private Credit-CCP), SailPoint ($SAIL public, take-private $6.9B Thoma Bravo Aug-2022, re-IPO Feb-2025), Omada, Netwrix, One Identity, Delinea Secret Server, Delinea Privilege Manager, plus AWS Secrets Manager, AWS Certificate Manager, AWS IAM Roles Anywhere, AWS Verified Access, AWS Cognito, Azure Key Vault, Azure Managed Identities, Azure AD B2C, Entra Workload ID, Google Secret Manager, Google Cloud Certificate Manager, Google Cloud IAP, Google Cloud IAM. Regulation, framework — NIST SP 800-207 Zero Trust, SP 800-207A, SP 800-63-4, SP 800-63C-4 (Aug-2024 IAL/AAL/FAL updates), SP 800-207 workload identity, SP 800-63C FedCM, OIDC, SD-JWT, NIST SP 800-53 Rev 5, SP 800-171 Rev 3, CMMC 2.0, FedRAMP-Moderate/High, IL4/5, StateRAMP, TX-RAMP, PCI-DSS 4.0.1 (Mar-2024, Mar-2025 deadlines, expanded auth requirements), HIPAA, HITECH, HITRUST r2, EU eIDAS 2.0, Digital Wallet, PSD3, DORA (Jan-2025), NIS2 (Oct-2024), EU AI Act Art. 50 for AI-agent identity, audit, EO 14028, M-22-09 (Zero Trust), M-24-14 (SBOM, attestation), plus post-Snowflake-token, Sisense, Cloudflare, Okta, GitHub-OAuth 2024 wave forcing board-level NHI, machine-identity procurement.

Why 2026 is different

Four unlocks: (1) The 2024 Snowflake stolen-token wave (Ticketmaster, AT&T, Santander, LendingTree, Advance Auto Parts, 165+ tenants via non-MFA'd service accounts, May-Jul-2024), Sisense breach (Apr-2024), Cloudflare-post-Okta compromise, GitHub OAuth-token compromises collapsed the 'is NHI a real category?' debate and forced every F500 CISO to procure NHI discovery, posture, rotation coverage. (2) The AI-agent explosion — OpenAI Agents SDK, Anthropic Claude Agent SDK, MCP OAuth 2.1 profile (Mar-2025), LangGraph, CrewAI, AutoGen, Temporal, Inngest, Trigger.dev, Cursor Background Agent, Devin sandbox — created millions of new machine, agent identities per enterprise, exploding the NHI-to-human ratio from 20-45:1 to 45-80:1 and making agent-identity, tool-authorization a board-level line item. (3) CyberArk-Venafi $1.54B (Oct-2024), IBM-HashiCorp $6.4B (pending Feb-2025), Auth0-Okta $6.5B legacy, SailPoint re-IPO Feb-2025, Ping-ForgeRock merger validated NHI, machine-identity as top-tier acquirer, IPO category and priced strategic exits at 10-20x ARR. (4) Regulation — NIST SP 800-207 Zero Trust, SP 800-63-4, SP 800-63C-4 (Aug-2024), M-22-09 (Zero Trust), PCI-DSS 4.0.1 (Mar-2024/Mar-2025), EU eIDAS 2.0, DORA (Jan-2025), NIS2 (Oct-2024), EU AI Act Art. 50 hard deadlines force NHI, agent-identity, audit-log coverage, unlocking a new $5-10B+ procurement line-item separate from human IAM.

Realistic capital stack

Seed $3-15M for founding-team, first published NHI coverage, blast-radius benchmark, 3-5 F500 or top-100-tech design-partner logos (Clutch $8.5M seed Feb-2024 Lightspeed-Merlin, Andromeda $10M seed May-2024 Foundation Capital, Natoma $6M seed Mar-2024 First Round-Dell Ventures, P0 $8M seed Lightspeed-Palo Alto). Series A $20-50M for 15-40 F500, top-100-tech logos, $2-8M ACV proof, FedRAMP, SOC 2 Type II, ISO 27001 (Oasis $35M A Jan-2024 Sequoia-Accel-Cyberstarts, Aembit $25M A Sep-2023 Acrew-Ballistic-Ten Eleven, Entro $18M A Nov-2023 Dell Ventures-StageOne, Token $20M A Feb-2024 Notable-TLV, Apono $12.5M A Redpoint-New Era, Astrix $25M A pre-Series B). Series B $30-120M for $10-40M+ ARR, NDR 130%+, FedRAMP-Moderate/High, IL4/5, Okta, Entra, Google, AWS, Azure, GCP, Kubernetes, Snowflake, Databricks, Salesforce, Workday, Slack, GitHub, GitLab, Bitbucket integration coverage (Astrix $45M B Nov-2024 Menlo-Bessemer-CRV-F2, Britive $20M B Pelion-Crosslink, Corsha $12M A Ten Eleven pattern). Series C+ $80M-$300M for $50M-$200M+ ARR, platform, M&A, late-stage growth (Silverfort $116M D Jul-2024 Brighton Park-Greenfield-Acrew, Grip $41M C Sep-2024 YL-Third Point-Intel, Teleport $110M C Nov-2021 Bessemer-Insight-Kleiner-S28-YC, StrongDM $54M B Feb-2022 Sequoia-Godfrey-Tiger). Non-dilutive, credits: NSF SBIR-STTR, DARPA, IARPA, DoD SBIR, DIU, AFWERX, CISA JCDC, CISA JSC, CISA Secure by Design, NSA Cybersecurity Directorate, NIST NCCoE, UK NCSC, Innovate UK, EU Horizon-EIC, ENISA, plus AWS, Azure, Google, Nvidia partner-credits ($100k-$500k per startup).

Common failure modes

Building an NHI product without a published discovery, coverage benchmark against a real F500 or top-100-tech reference — buyers evaluate against Astrix, Oasis, Silverfort, Grip, Savvy incumbents, and any pitch without a 90%+ NHI coverage, 70-90% over-permissioned/stale-NHI reduction case-study gets binned. Ignoring SPIFFE/SPIRE, OAuth 2.1, FedCM, SD-JWT, Verifiable Credentials, mDL, MCP OAuth 2.1 as the reference standards — bespoke identity primitives are a losing tax and hyperscaler, Okta, CyberArk will crush at scale. Building agent-identity or NHI-remediation without human-in-loop approval, audit-log, rollback, blast-radius-limits — a single bad auto-revocation or token-rotation that breaks prod erases the CISO trust flywheel. Ignoring FedRAMP-Moderate/High, IL4/5, SOC 2 Type II, ISO 27001, ISO 42001, PCI-DSS 4.0.1, HIPAA, HITRUST r2, FIPS 140-3 — these are gating for gov, defense, finance, healthcare procurement, not nice-to-have. Building NHI-discovery-only without a rotation, governance, JIT-elevation, secretless workflow — F500 CISOs bin observability-only pitches that don't close the loop. Ignoring Okta, Microsoft Entra, Google Workspace, Amazon IAM, CyberArk, HashiCorp Vault, Delinea, SailPoint, Ping, Saviynt as the reference IAM, PAM, governance incumbents' partner-programs, marketplaces — bundled identity inside Okta Workflows, Entra ID Governance, Verified Permissions, IAM Identity Center is 40-60% of the F500 baseline. Ignoring the CyberArk-Venafi $1.54B, IBM-HashiCorp $6.4B, Auth0-Okta $6.5B, Ping-ForgeRock, SailPoint-Thoma Bravo strategic acquirer pattern — most exits will be strategic, not IPO.

Frequently asked questions

Is there room for another NHI or machine-identity startup vs. Okta, CyberArk, Microsoft Entra, HashiCorp-IBM, Silverfort?
Yes, at the NHI-first, agent-first, workload-first, regulated-vertical layers where incumbents optimize for their own installed base. Defensible wedges are (a) NHI discovery, posture, governance across SaaS, IaaS, PaaS (Astrix, Oasis, Clutch, Andromeda, Token, Natoma, Entro, Grip, Savvy, Silverfort), (b) workload-to-workload, secretless, SPIFFE/SPIRE (Aembit, Corsha, HashiCorp Boundary-IBM, Teleport, StrongDM), (c) JIT, cloud PAM for humans, machines (Britive, Apono, P0, ConductorOne, Opal, Rezonate), (d) secrets-detection, rotation, vaulting (GitGuardian, Truffle, Doppler, Infisical, Akeyless), (e) machine identity, code-signing, PKI, certificate lifecycle (Venafi-CyberArk, DigiCert-Clearlake, Keyfactor, Smallstep, Chainguard), (f) AI-agent identity, MCP OAuth, tool-authorization, agent-guardrails (emerging greenfield 2024-2025).
How exposed is an NHI startup to Okta, Microsoft Entra, Google, AWS bundled identity?
Meaningfully — Okta Workflows, Auth0, Governance, Microsoft Entra ID, Entra ID Governance, Entra Workload ID, Purview, Defender for Cloud, Google Cloud Identity, BeyondCorp, Chronicle-Mandiant, Amazon IAM, IAM Identity Center, Verified Permissions, Cognito all have platform, data-gravity, procurement advantages inside their installed bases. Defensible wedges are (a) multi-IdP, multi-cloud neutrality (customers don't want Okta-only or Entra-only NHI coverage), (b) NHI-first, agent-first architecture where human-IAM incumbents lag on service-account, OAuth-app, workload, agent coverage, (c) depth-of-governance, JIT, secretless, rotation-automation where bundled identity ships baseline coverage, (d) regulated, defense, on-prem, air-gapped where SaaS-only bundled identity can't deploy, (e) MCP OAuth 2.1, agent-tool-authorization, agent-guardrails where hyperscaler, IdP incumbents are still building out.
Realistic exit?
Strategic acquisition dominates. Recent comps: Venafi-CyberArk $1.54B Oct-2024, HashiCorp-IBM $6.4B pending Feb-2025, Auth0-Okta $6.5B May-2021, Ping-Thoma Bravo take-private $2.8B Aug-2022, ForgeRock $2.3B Aug-2023 merger, SailPoint-Thoma Bravo take-private $6.9B Aug-2022, re-IPO Feb-2025 $SAIL, Saviynt $205M growth AB Private Credit-CCP, Wiz-Google $32B pending Mar-2025 (CNAPP-adj), Ermetic-Tenable $265M Sep-2023 (CIEM), Talon-Palo Alto $625M Nov-2023 (browser, SaaS identity), Silverfort $116M D Jul-2024 Brighton Park-Greenfield-Acrew, Grip $41M C Sep-2024 YL-Third Point-Intel, Astrix $45M B Nov-2024 Menlo-Bessemer-CRV, Oasis $35M A Jan-2024 Sequoia-Accel-Cyberstarts, Aembit $25M A Sep-2023 Acrew-Ballistic-Ten Eleven, Teleport $169M+ total, StrongDM $150M+ total, Okta $OKTA public $17B+ market-cap, CyberArk $CYBR public $16B+ market-cap. Likely strategic acquirers: Okta $OKTA, CyberArk $CYBR, Microsoft $MSFT, Google $GOOG, Amazon $AMZN, Palo Alto Networks $PANW, CrowdStrike $CRWD, Cisco-Splunk $CSCO, IBM-HashiCorp $IBM, Ping-Thoma Bravo, SailPoint $SAIL, Saviynt, Delinea-TPG, BeyondTrust, One Identity-Clearlake, Cloudflare $NET, Fortinet $FTNT, Zscaler $ZS, Wiz-Google, plus PE consolidators Vista, Thoma Bravo, Clearlake, Francisco, KKR, TPG, Bain, Hellman & Friedman, TA Associates for take-private roll-ups. IPO reserved for two or three category leaders at $200M+ ARR — Silverfort, Astrix, Oasis, and Aembit are current candidates on a 3-5 year horizon.

Related fundraising verticals (40)

Investor directory · Fundraising library · Articles A–Z · Company funding database